CVE-2025-59797

Profession Fit 5.0.99 Build 44910 allows authorization bypass via a direct request for /api/challenges/{id} and also URLs for eversports, the user-management page, and the plane page.
Configurations

No configuration.

History

22 Sep 2025, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-22 13:16

Updated : 2025-09-22 21:22


NVD link : CVE-2025-59797

Mitre link : CVE-2025-59797

CVE.ORG link : CVE-2025-59797


JSON object : View

Products Affected

No product.

CWE
CWE-425

Direct Request ('Forced Browsing')